URLhaus Database

You are currently viewing the URLhaus database entry for http://172.245.210.119/.rIIo5x93/JFS.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2237624
URL: http://172.245.210.119/.rIIo5x93/JFS.mpsl
URL Status:Offline
Host: 172.245.210.119
Date added:2022-06-14 10:23:04 UTC
Last online:2022-06-16 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2022-06-14 10:24:05 UTC to report{at}virmach[dot]com)
Takedown time:2 days, 7 hours, 54 minutes Poor (down since 2022-06-16 18:18:45 UTC)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-16n/aelf 8021eb618ae11a3126dbbe5c3b1b8da53083f71fef89ec9fbe6f1c3585366f23Virustotal results 28.57% 
2022-06-16n/aelf 21fe3cb24ae98ec459a75e530d533ef63353c10deb0cfd0fc4dec551a9cbf2dfn/a 
2022-06-16n/aelf 28c7d1421acf61541531e2414f2a47f9df660772e506891a95a7b43225c8fb22n/a 
2022-06-16n/aelf a061f820f2d0e10d70535ce875d6ebb2abbd138af987ff5212a0420b85e6dde3n/a 
2022-06-15n/aelf 8948382f6b681444a6b084546dbe7f0b4d90db85f3bd23abc86e3815e5c4da71n/a 
2022-06-15n/aelf f83d492320a6e28fd6f693528a548aaf49867dcd340b74f3eb63e2efe74d1581n/a 
2022-06-15n/aelf 41e883525db072ba356b180b6770f602ff4ef0d24b8cf23270a63804c9d05943n/a 
2022-06-15n/aelf 3cfbb8cd07864ad709b2ff8449802d369c25547dc967eb281a96ff7f0dd3abacn/a 
2022-06-14n/aelf 598f4f9598a0bff900a794326491b84f4a4d3c4a22c1b213bb0656a637ceda7eVirustotal results 29.31%Mirai